Last updated: 22 April 2020
Welcome to SmartFrame Technologies Ltd. This policy explains how we handle and use your personal information, and your rights in relation to that information. This document forms a part of our organization’s commitment to meeting the requirements of the General Data Protection Regulation (EU) 2016/679 (GDPR).
SmartFrame Technologies Ltd is a data controller in relation to the processing activities described below, and references to “we”, “our” or “us” refers to SmartFrame Technologies Ltd. A “data controller” is the organization that decides why and how your personal information is processed.
This policy describes the way we handle and use the personal information that we obtain from all the different interactions you may have with us as a business. This includes information obtained from your visits to our website or social media pages; when you use our products and services; when you contact us; use our applications; and take part in any of our competitions or promotions. SmartFrame Technologies Ltd is the data controller in relation to the processing activities described below. This means that SmartFrame Technologies Ltd decides why and how your personal information is processed.
Please see the section at the end of this policy for our contact and legal information.
1. Responsible operation
We do not, and will not, knowingly collect information from any person under the age of 18.
If you are under the age of 18, and wish to use our products and service, you must not use our website or submit any personal information. A parent or legal guardian must open and administer the account on your behalf.
Due to the nature of images available online that may be using SmartFrame Technologies Ltd’s products and services, the potential exists for these images to contain mature subject matter. The responsibility for sharing any content using SmartFrame Technologies Ltd’s features rests upon the good judgment of anyone using SmartFrame Technologies Ltd’s products and services.
2. Collection of personal information
We receive personal information about you in a number of ways. This includes, but is not limited to, information that you provide us; that we collect from your visits to our website; from applications and social media pages; and that obtained from other sources. We only collect personal information which we need, and which is relevant for the purposes for which we intend to use it.
We collect the following information if you choose to give it to us in connection with your account registration on our website, applications, social media pages, when exercising your legal rights or by corresponding with us by phone, email or other means and is provided by you entirely voluntarily. The information you give to us can include your name, contact details (such as phone number, email address and postal address), enquiry details, your opinion of our products and services and certain marketing preferences.
There are some circumstances where we need the information (pursuant to our contract with you), for example, where you have a technical issue we may need to know certain details about your computer or accounts and services you may be using such as email services, web development platform, Internet Service provider (ISP), etc. If you don’t provide us with this information we may not be able to provide our services to you or be able to interact with you in the way you would expect.
Here is a list of the personal data fields that we need to fulfil our contract for our services:
• Your name, title and contact details (email address, telephone number, postal address, social media handle); demographic information may be collected; however specific identifiers such as date of birth will not be
• Any information you include in correspondence you send to us or in forms you submit to us at or when using our Site, Applications or social media pages
• Details of your orders and purchases
• Your marketing preferences
• The opinions and other information you provide when responding to customer surveys and product reviews
• Information you provide from Companies House such as VAT number and Company Registration
• Any personal information included in your entries to competitions that we run
• Your identification information when exercising the rights that you have in relation to our processing of your personal information (see further Your rights in relation to your personal information)
• Details of any transactions between you and us
• Information you give us when you contact us with a query or issue;
• Your payment card details and, in relation to certain refunds, your bank account details;
• The internet protocol (IP) address of your device and details regarding the type of device and browser software you use to access the website.
• Details of your use of our website and apps, namely traffic data, weblogs and statistical data, including where and when you clicked on certain parts of our website and details of the webpage from which you visited it
• The date and time you used our website the pages you visited on our website and how long you visited us for
• Your GPS location (where you have permitted access to this)
• The website address from which you accessed our website (referral link)
• Information we collect about you from other sources.
3. Use of your personal information
We use your personal information for a variety of reasons. We rely on different legal grounds to process your personal information, depending on the purposes of our use and the risks to your privacy. You will only receive unsolicited email marketing communications from us if: (a) we have obtained your details in the course of a sale or negotiation for a sale of our products or services and you have not objected to receiving such direct email marketing from us.
Of course, we will only send you marketing emails that are based on similar products or services that you purchased from us and you will always have the opportunity to opt out at any time; or (b) if you have consented to receiving marketing email from us (you can opt-out of receiving them at any time).
We do not share your personal information with companies that would send their marketing to you without your consent.
3.1 Where you have provided consent
We may use and process your personal information for the following purposes where you have consented for us to do so:
To contact you via email with marketing information about products, events, product launches, exciting offers and services (see Marketing for further details).
3.2 Where necessary to comply with our legal obligations
We will use your personal information to comply with our legal obligations:
To keep a record relating the exercise of any of your rights relating to our processing of your personal information; to take any actions in relation to health and safety incidents required by law; and to handle and resolve any complaints we receive relating to the services and products we provide.
3.3 Where necessary for us to pursue a legitimate interest
We may use and process your personal information where it is necessary for us to pursue our legitimate interests as a business for the following purposes: processing necessary for us to promote our business, brands and products and measure the reach and effectiveness of our campaigns for analysis and insight conducted to inform our marketing strategies, and to enhance your visitor experience; to tailor and personalize our marketing communications based on your attributes, for example, by sending you a birthday treat message; to fulfil and complete your orders, purchases and other transactions entered into with us; to contact you with targeted advertising delivered online through social media and other online platforms operated by other companies, unless you object.
You may receive advertising based on information about you that we have provided to our Customer Relationship Management (CRM) system or because, at our request, the CRM has identified you as having similar attributes to the individuals whose details it has received from us.
We collect and analyze this information in this way so that we can deliver the most appropriate customer experience to you by tailoring and making relevant all our service and communications. This processing includes:
• Processing necessary for us to support you with your enquiries to respond to correspondence you send to us and fulfil the requests you make to us.
• Processing necessary for us to respond to changing market conditions and the needs of our customers to analyze, evaluate and improve our products and services so that your visit and use of our Website, Apps, services, social media pages are more useful and enjoyable (we will generally use data amalgamated from many people so that it does not identify you personally)
• Processing necessary to undertake market analysis and research (including contacting you with customer surveys) so that we can better understand you as a customer; for future product development purposes.
• Processing necessary for us to operate the administrative and technical aspects of our business efficiently and effectively to administer our Website, Applications and our social media pages and for internal operations, including troubleshooting, testing, statistical purposes; for the prevention of fraud and other criminal activities; to verify the accuracy of data that we hold about you and create a better understanding of you as an account holder or visitor; for network and information security in order for us to take steps to protect your information against loss or damage, theft or unauthorized access; to comply with a request from you in connection with the exercise of your rights (for example where you have asked us not to contact you for marketing purposes, we will keep a record of this on our suppression lists in order to be able to comply with your request); for the purposes of corporate restructure or reorganization or sale of our business or assets; for efficiency, accuracy or other improvements of our databases and systems, for example, by combining systems or consolidating records we hold about you; to enforce or protect our contractual or other legal rights or to bring or defend legal proceedings.
• Processing to inform you of updates to our terms and conditions and policies; and for other general administration including managing your queries, complaints, or claims, and to send service messages to you.
3.4 Where necessary for us to carry out pre-contract or contract performance you have requested
We will use your personal information where this is necessary for us to perform our contract with you or to carry out any pre-contract steps you’ve asked us to so that you can enter into that contract, for the following purposes:
To process, fulfil and complete your orders, purchases and other transactions entered into with us and deliver your order and deliver your order; to process your payment card or bank details when taking payment for your orders or when providing a refund; and to run our competitions and promotions that you enter from time to time and to distribute prizes.
4. Disclosure of your personal information by us
We only disclose your personal information outside our business in limited circumstances. If we do, we will put in place a contract that requires recipients to protect your personal information, unless we are legally required to share that information. Any contractors or recipients that work for us will be obliged to follow our instructions. We do not sell your personal information to third parties.
We may disclose your information to our third-party service providers, agents and subcontractors (suppliers) for the purposes of providing services to us or directly to you on our behalf, including the operation and maintenance of our Website, Applications and social media pages.
Our suppliers can be categorized as follows:
• Advertising, PR, digital and creative agencies
• Banks, payment processors and financial services providers
• Cloud software system providers, including database, email and document management providers
• Customer care/services providers (Support)
• Delivery and mailing services providers
• Facilities and technology service providers including scanning and data destruction providers
• Health and safety claims administrators and consultants
• Insurers and insurance brokers
• Legal, security and other professional advisers and consultants
• Market and customer research providers
• Service Providers for email marketing campaigns
• Social media platforms
• Website and App developers
• Website and data analytics platform providers
• Website hosting services providers
When we use Suppliers, we only disclose to them any personal information that is necessary for them to provide their services and only where we have a contract in place that requires them to keep your information secure and not to use it other than in accordance with our specific instructions.
We may disclose the personal information to other third parties as follows:
Any third party who is restructuring, selling or acquiring some or all of our business or assets or otherwise in the event of a merger, organization or similar event; and if we are under a duty to disclose or share your information in order to comply with any legal or regulatory obligation or request, including by the police, courts, tribunals or regulators.
5. Transfers of your personal information outside of Europe
We transfer your personal information outside of Europe. We take measures to protect your personal information. The personal information you provide to us may be transferred or stored in countries located outside of the European Economic Area (EEA). By way of example, if any of our servers or those of our third-party service providers are from time to time located in a country outside of the EEA or if our third-party suppliers themselves send personal Information out of the EEA. These countries may not have similar data protection laws to the UK and may not have adequate data protection laws equivalent to those in the EEA. The non-EEA countries to which we transfer your personal data are: The USA.
If we (or our third-party suppliers) transfer or store your information outside of the EEA in this way, we will take steps to ensure that appropriate security measures are taken with the aim of ensuring that your privacy rights continue to be protected as outlined in this policy. These steps include imposing contractual obligations on the recipient of your personal information or ensuring that the recipients are subscribed to ‘international frameworks’ that aim to ensure adequate protection. Please contact us using the details at the end of this policy for more information about the protections that we put in place and to obtain a copy of the relevant documents.
If you use our services whilst you are outside the EEA, your information may be transferred outside the EEA in order to provide you with those services.
6. Security and links to other websites
We take the security of your personal information seriously and use a variety of measures based on good industry practice to keep it secure. Nonetheless, transmissions over the internet and to our Website, Applications and our social media pages may not be completely secure, so please exercise caution. When accessing links to other websites, their privacy policies, not ours, will apply to your personal information.
We employ security measures to protect the personal information you provide to us, to prevent access by unauthorized persons and unlawful processing, accidental loss, destruction and damage. When we have provided (or you have chosen) a password allowing you access to certain parts of the Site, you are responsible for safeguarding it and keeping it confidential and you promise not to allow it to be used by third parties.
6.1 Payment Security
We use the following software to manage our payments and invoicing processes Xero, Salesforce, Stripe, Breadwinner and Blackthorn
This technology includes the following features:
- Authentication: this assures your browser that your data is being sent to the correct computer server, and that the server is secure.
- Encryption: this encodes the data, so that it cannot be read by anyone other than the secure server.
- Data Integrity: this checks the data being transferred to ensure it has not been altered.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do everything possible to protect your personal information, we cannot guarantee the security of any personal information during its transmission to us online. You accept the inherent security implications of using the internet and will not hold us responsible for any breach of security unless we are at fault.
If you are using a computer or terminal in a public location, we recommend that you always log out and close the website browser when you complete an online session for your security. In addition, we recommend that you take the following security measures to enhance your online safety:
• Keep your operating system and applications up-to-date
• When creating a password, we recommend using at least 10 characters with a combination of letters and numbers
• We recommend the use of a password manager
• Activation of 2-factor authentication on your online accounts
• Registration of your email address at haveibeenpwnd.com
• Keep your passwords private. Remember, anyone who knows your password may access your account. Avoid using the same password for multiple online accounts.
• We will never ask you to confirm any account or credit card details via email. If you receive an email claiming to be from smartframe.io or SmartFrame Technologies Ltd asking you to do so, please contact us immediately and do not respond.
In addition, if you linked to our website from a third-party website, we cannot be responsible for the privacy policies and practices of the owners and operators of that third-party website and recommend that you check the policy of that third-party website.
7. The periods for which we retain your personal information
We will not hold your personal information in an identifiable format for any longer than is necessary for the purposes for which we collected it. For certain purposes we retain your personal information indefinitely (e.g. to suppress marketing messages) whilst for others we retain it for a period of seven years after the information is no longer required for business reasons so that we can deal with any legal proceedings that could arise.
The only exceptions to the periods mentioned above are where:
You exercise your right to have the information erased (where it applies) and we do not need to hold it in connection with any of the reasons permitted or required under the law (see further Your rights in relation to your personal information)
You exercise your right to require us to retain your personal information for a period longer than our stated retention period (see further Your rights in relation to your personal information);
We bring or defend a legal claim or other proceedings during the period we retain your personal information, in which case we will retain your personal information until those proceedings have concluded and no further appeals are possible; or in limited cases, existing or future law or a court or regulator requires us to keep your personal information for a longer or shorter period.
We retain an anonymized version of the submitted personal information for as long as we require it for reporting and other statistical and analytical purposes. Such anonymized information will not identify you and may be derived from personal information that was contained within accounts that have subsequently been deleted.
8. Your rights in relation to your personal information
You have a number of rights in relation to your personal information under the GDPR. In relation to certain rights, we may ask you for information to verify your identity and, where applicable, to help us to search for your personal information. Except in rare cases, we will respond to you within 30 days after we have received this information or, where no such information is required, after we have received full details of your request.
• To have your personal information corrected if it is inaccurate and to have incomplete personal information completed;
• To object to processing of your personal information;
• To withdraw your consent to processing your personal information;
• To restrict processing of your personal information;
• To have your personal information erased;
• To request access to your personal information and information about how we process it;
• To electronically move, copy or transfer your personal information in a standard, machine-readable form; and
• Rights relating to automated decision making, including profiling.
Please check this page regularly for changes to this policy. We will email you with changes if we hold a valid email address for you.
We may review this policy from time to time, and any changes will be notified to you by posting an updated version on our Site and/or by contacting you by email. We recommend you regularly check this page for changes and review this policy each time you visit our Site.
10. Contact and legal information
You can contact us with your queries in relation to this policy or for any other reason by post, email or by phone.
SmartFrame Technologies Ltd
3 Lloyd’s Avenue